CyNtell offers seven penetration testing disciplines plus a recurring vulnerability scanning program. Most engagements combine two or three, an external network test with a web application test, or a Microsoft 365 assessment with phishing simulation. CyNtell scopes what your environment and your compliance obligations actually call for rather than selling a fixed package.
01
Network penetration testing, external and internal
External testing works from the public internet inward: what an attacker sees with no credentials and no access. Internal testing starts from an assumed breach, a compromised laptop or a contractor's account, and answers the question that decides how bad a breach gets: once someone is inside, how far can they move, and what do they reach? For defense contractors that second answer is the one that matters, because it establishes whether a foothold anywhere becomes access to CUI.
Evidence for RA.L2-3.11.1 · CA.L2-3.12.1 · PCI DSS 11.4.2 / 11.4.3 · CIS 18.2 / 18.5
02
Wireless penetration testing
CyNtell wireless penetration testing checks whether your wireless perimeter, which extends into the parking lot, actually holds. CyNtell tests authentication and encryption on corporate and guest networks, looks for rogue and mis-scoped access points, and checks whether guest wireless is genuinely segmented from the network that handles regulated data, or only labelled that way. Segmentation that exists on the diagram but not in the switch configuration is one of the most common findings CyNtell reports.
Relevant to CUI enclave boundary validation and PCI DSS segmentation testing 11.4.5
03
Web and mobile application testing
Applications are the front door most attackers try first. CyNtell tests against the OWASP Web Security Testing Guide: authentication and session handling, access control between user roles, injection, business logic that can be driven somewhere it was never meant to go, and API endpoints that enforce less than the interface in front of them. Mobile applications are tested against the OWASP Mobile Application Security Testing Guide, including what the app stores on the device.
Methodology: OWASP WSTG v4.2 · OWASP MASTG / MASVS · supports PCI DSS 11.4.1 application-layer testing
04
SaaS platform assessment
You cannot penetration test a vendor's platform, their terms forbid it and it is not your system to test. What you can and should assess is your tenant: how it is configured, who has access, what integrations and OAuth grants are connected, how data leaves, and whether an offboarded employee's access truly ended. In most organizations the SaaS estate has grown faster than anyone's ability to inventory it, and third-party app grants are where CyNtell finds the quiet standing access nobody remembers approving.
Supports AC.L2-3.1.1 access control and 3.1.2 transaction limits · SOC 2 CC6.1 · ISO 27001 A.8.8
05
Microsoft 365 and GCC High assessment
Almost every defense contractor's CUI passes through Microsoft 365, and almost nobody assesses the tenant itself. CyNtell reviews Entra ID conditional access and privileged roles, Exchange Online mail flow and external forwarding, SharePoint and OneDrive sharing defaults, Teams external access, Intune device compliance, and audit logging, then checks the boundary that actually matters for compliance: whether CUI is confined to the environment you claim it lives in, or has quietly spilled into a commercial tenant that was never in scope.
Directly supports the CUI boundary claim in your SSP · SC.L2-3.13.1 boundary protection · AU.L2-3.3.1 audit logging
06
Physical security testing
CyNtell physical security testing establishes whether someone can simply walk in. Digital controls do not help if they can. CyNtell tests entry controls, badge and visitor procedures, reception and tailgating resistance, server room and wiring closet access, clean-desk practice, and the disposal path for media and printed material. For contractors with a physical CUI handling requirement, this is where the paper copy of the thing you spent a year protecting electronically tends to be found.
Evidence for the PE (Physical Protection) family · MP.L2-3.8.3 media sanitization
07
Social engineering and phishing simulation
Phishing simulation sent to your workforce, built to look like mail your people would plausibly receive, not the obvious template everyone already knows to report. CyNtell measures who clicked, who submitted credentials, who reported it, and how quickly, then turns that into targeted training rather than a shaming exercise. Pretexting by phone is available in scope where you want it. Reporting rate matters more than click rate: an organization where people raise their hand fast is one that survives the campaign that eventually works.
Supports AT.L2-3.2.1 / 3.2.2 awareness training · CIS 14.x · pairs with CyNtell security awareness training
08
Recurring vulnerability scanning
A penetration test is a point in time. The requirement most organizations actually carry is continuous: scan on a defined schedule, scan again when new vulnerabilities are published, and remediate on a risk basis. CyNtell runs that program as a subscription, authenticated and unauthenticated scanning against your defined schedule, findings triaged by a human so you get a real queue rather than raw tool output, remediation tracking, and a periodic evidence artifact written to be handed straight to an assessor or auditor.
This is the requirement itself: RA.L2-3.11.2 scan · RA.L2-3.11.3 remediate · GLBA 16 CFR 314.4(d) six-month cadence · PCI DSS 11.3